Software architect Eric McDonald discovered a security vulnerability in the 2021 Honda Civic infotainment system that allows unauthorized users to install custom software via the vehicle's USB port.
Key Points
- The vulnerability stems from the head unit accepting AOSP files signed with a publicly known test key.
- Attackers with temporary physical access can install malware to record conversations, track location, and capture video.
- Captured data can be exfiltrated using the vehicle's built-in Bluetooth, Wi-Fi, or cellular connectivity.
- The flaw is limited to the infotainment system and does not grant control over engine, braking, or safety features.
- Similar vulnerabilities may exist in other vehicle makes that share identical infotainment hardware or software components.